Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2021-45100
The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabl…
Ksmbd
after 3.4.2
MEDIUM 6.8
CVE-2021-44518
An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing code before each operation (…
Egeetouch Manager
No fix yet
HIGH 8.1
CVE-2021-44480
Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen to a device's surroundings v…
Wokka Watch Q50 Firmware
Mitigation only
MEDIUM 5.9
CVE-2021-38978
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to pro…
Security Guardium Key Lifecycle Manager
after 4.0.0.3
MEDIUM 5.3
CVE-2021-3792
Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the co…
Halo\+ Camera Firmware
03.40.00 / 03.40.02+
HIGH 7.4
CVE-2021-40366
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V11.34). Th…
Climatix Pol909 Firmware
11.34 / 11.42+
MEDIUM 5.9
CVE-2020-4152
IBM QRadar Network Security 5.4.0 and 5.5.0 transmits sensitive or security-critical data in cleartext in a communication channel that can be obtaine…
Qradar Network Security
5.4.0.14 / 5.5.0.9+
MEDIUM 6.5
CVE-2021-3774
Meross Smart Wi-Fi 2 Way Wall Switch (MSS550X), on its 3.1.3 version and before, creates an open Wi-Fi Access Point without the required security mea…
Mss550x Firmware
after 3.1.3
MEDIUM 5.9
CVE-2021-29753
IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it…
Business Automation Workflow
Mitigation only
MEDIUM 5.9
CVE-2021-42699
The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain th…
Daqfactory
after 18.1
MEDIUM 5.9
CVE-2021-38418
Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and pe…
Dialink
after 1.2.4.0
HIGH 7.5
CVE-2021-43270
Datalust Seq.App.EmailPlus (aka seq-app-htmlemail) 3.1.0-dev-00148, 3.1.0-dev-00170, and 3.1.0-dev-00176 can use cleartext SMTP on port 25 in some ca…
Seq.app.emailplus
Patch available
HIGH 8.2
CVE-2021-39341EPSS 22%
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorizatio…
Optinmonster
after 2.6.4
HIGH 7.4
CVE-2021-0296
The Juniper Networks CTPView server is not enforcing HTTP Strict Transport Security (HSTS). HSTS is an optional response header which allows servers …
Ctpview
Mitigation only
HIGH 7.5
CVE-2021-20599
Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/…
R08sfcpu Firmware
Mitigation only
MEDIUM 5.3
CVE-2021-39882
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
GitLab
14.1.7 / 14.2.5+
HIGH 7.5
CVE-2020-20128
LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers.
Laracms
No fix yet
HIGH 7.5
CVE-2021-22946
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the…
Curl
7.79.0+
HIGH 7.5
CVE-2021-39342
The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenev…
Financial
1.4.9+
MEDIUM 5.3
CVE-2021-36165
RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as ba…
S9922l Firmware
No fix yet
HIGH 8.1
CVE-2021-40847EPSS 10%
The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root…
R6400v2 Firmware
No fix yet
HIGH 8.8
CVE-2021-38142
Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades. An attacker on the local network can achie…
Mirrorop Windows Sender
2.5.3.65+
MEDIUM 5.9
CVE-2021-39272
Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.
Fedora
6.4.22+
HIGH 7.5
CVE-2021-33883
A Cleartext Transmission of Sensitive Information vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote attacker to obtain sensitiv…
Spacecom2
012u000062+
MEDIUM 5.3
CVE-2021-38373
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" …
Kmail
Mitigation only
MEDIUM 5.3
CVE-2021-22923
When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those sam…
Curl
1.0.1.1 / 7.78.0+
HIGH 7.5
CVE-2021-33900
While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-…
Directory Studio
after 1.5.3
HIGH 7.5
CVE-2020-36423
An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't prop…
Debian Linux
2.16.7 / 2.23.0+
MEDIUM 6.5
CVE-2020-4980
IBM QRadar SIEM 7.3 and 7.4 uses less secure methods for protecting data in transit between hosts when encrypt host connections is not enabled as wel…
Qradar Security Information And Event Manager
7.3.3 / 7.4.3+
MEDIUM 5.3
CVE-2020-12730
MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.
Flamingo 2 Firmware
Mitigation only